Philips and GE investigating Clop ransomware data theft claims

Two global tech giants, General Electric (GE) and Philips, have joined oil giant Shell in investigating claims that their systems were breached by the notorious Clop ransomware gang. The alleged data theft incident has sparked concerns about the security of enterprise software platforms widely used across various industries.

According to reports, the Clop hacking group has claimed to have stolen 89GB of sensitive data from the three companies’ compromised systems. This comes after PTC, the vendor of the affected software platforms, released a critical security patch for an improper input validation vulnerability (CVE-2026-12569) in June. However, it appears that some companies failed to apply the fix promptly, leaving their systems vulnerable to attacks.

The Clop gang has been exploiting this vulnerability to deploy JSP webshells on compromised PLM platforms, allowing them to steal sensitive data from victims’ systems. This type of attack is particularly concerning because it allows attackers to gain access to confidential information, including project plans, photos of facilities, drawings, and diagrams.

While the three companies have yet to share more details about the incident, it’s clear that this vulnerability has been actively exploited in attacks worldwide. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) confirmed that the flaw is being used by attackers, and German authorities have taken emergency action to warn PTC customers to patch their systems as quickly as possible.

The Clop extortion gang has a long history of targeting enterprise platforms in data theft attacks, breaching various file-sharing servers and exploiting zero-day flaws in software platforms. Their list of victims includes many high-profile organizations worldwide, including The Washington Post, Harvard University, and American Airlines subsidiary Envoy Air.

This incident serves as a stark reminder that even with security patches available, companies may still fail to apply them promptly, leaving their systems vulnerable to attacks. It’s essential for companies to prioritize cybersecurity and ensure that all software platforms are up-to-date with the latest security patches.

In practical terms, this means that companies should regularly review their security measures, including patch management policies, to prevent similar incidents in the future. They should also educate employees about the importance of cybersecurity and encourage them to report any suspicious activity promptly. By taking proactive steps to secure their systems, companies can reduce the risk of data theft and protect sensitive information from falling into the wrong hands.


Source: Bleeping Computer — 2026-08-17